Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding

webflare.beer

TLP:CLEAR
Active

Domain

Description

WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliate...

Sightings (0)

No sightings recorded yet

Details

Name / Label
How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding
Pattern Type
STIX
Confidence
75%
Valid From
Aug 11, 2026 18:02
Total Sightings
0
Added
Aug 11, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of webflare.beer

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.